CVE-2020-7869 Information
Jun 07, 2022
cve
Description
An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker to create arbitrary file. The ZOOK viewer has the \Tight file CMD\ function to create file. An attacker could create and execute arbitrary file in the ZOOK agent program using \Tight file CMD\ without authority.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36090
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: